CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/multi-tool-finding-triage

Merges two or more security scanner reports into one gate. Use when you need a single BLOCK or PASS decision from multiple scanners instead of reading N separate reports. Normalizes each report into one common finding format (a canonical `Finding`), deduplicates on a per-domain key while recording which scanners agree (`caught_by` consensus), validates a waiver (finding-suppression) file, rejecting any missing `expires:` / `approved_by:` / `reason:` or expired, enriches CVE findings with EPSS (exploit-probability) and CISA KEV (known-exploited catalog), then applies a `fail_on` severity threshold to emit BLOCK or PASS plus a bucketed pull-request comment. Works across static (SAST), dynamic (DAST), secret, dependency (SCA), container, and IaC scanners. To run a single scanner instead use semgrep-rules, codeql-queries, or one of the language-native-sast linters; this runs after them to merge output - the cross-scanner gate, not a single-scanner wrapper.

77

Quality

97%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

Overview
Quality
Evals
Security
Files

Quality

Content

100%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This is a model skill body: a dense 7-step pipeline with complete inline code, concrete halt and validation checkpoints, a fully worked end-to-end example, an anti-patterns table with fixes, and honest limitations. Structure and token budget are both well managed, with details correctly pushed one level deep into clearly labeled reference files.

DimensionReasoningScore

Conciseness

The body is lean and assumes competence: no explanation of what SAST, SARIF, or CVEs are (only one-line glosses like 'CISA KEV (known-exploited catalog)' that disambiguate rather than teach), a one-line pipeline diagram instead of prose, and every section (steps, worked example, anti-patterns, limitations) carries unique method content. It fits 'every token earns its place'; version numbers and dates that appear (scanner versions, `2026-12-31`) are illustrative example data, not aging API guidance, so the time-sensitivity penalty does not apply.

5 / 5

Actionability

Fully executable guidance: complete Python functions (`dedupe`, `priority`, `validate_waiver`), a copy-paste CI yaml with real action versions and a working `gh pr comment` invocation, exact report templates, and a worked example that walks one commit through every step with concrete values (`log4j-core@2.14.1`, `fail_on: critical`). The few deferred pieces (per-domain key table, verdict function) are precisely described in-body ('any surviving finding at or above `fail_on` returns BLOCK') and live one reference away, so nothing needed to execute is vague.

5 / 5

Workflow Clarity

Seven clearly sequenced steps with explicit halt/validation checkpoints: Step 1 halts on `NO_SCANNER_OUTPUT` and on a configured-but-silent scanner, Step 5 validates every waiver field and reports rejections rather than no-op'ing, Step 6 runs the verdict on the post-waiver list, and the exit-code contract ('exits non-zero on BLOCK') is stated. Error-recovery guidance is present ('After the fixes, re-run the scanners and this triage') and the anti-patterns table names failure modes with fixes — matching the level-5 anchor with feedback loops despite this being a batch/gate operation.

5 / 5

Progressive Disclosure

A clear overview (pipeline diagram plus differentiation axis) with well-signaled, one-level-deep references that all exist on disk: each of the three links is preceded by exactly what it contains ('The per-domain `key_fn` table, the class-normalization step... : references/finding-normalization.md'), and no reference points to another reference. Detail (severity anchor tables, waiver YAML schema, tuning basis) is appropriately split out while the method stays inline.

5 / 5

Total

20

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: it covers a complete multi-step capability concretely, gives an explicit trigger clause, and explicitly disambiguates from single-scanner sibling skills. The only defect is second-person phrasing ('Use when you need') in the trigger clause, which costs it a point on specificity under the rubric's voice rule.

DimensionReasoningScore

Specificity

The description lists multiple concrete, comprehensive actions ('Normalizes each report into one common finding format (a canonical `Finding`)', 'deduplicates on a per-domain key', 'validates a waiver (finding-suppression) file, rejecting any missing `expires:` / `approved_by:` / `reason:` or expired', 'enriches CVE findings with EPSS... and CISA KEV', 'applies a `fail_on` severity threshold to emit BLOCK or PASS'), matching the level-5 anchor. It is reduced by 1 because the trigger clause 'Use when you need a single BLOCK or PASS decision' uses second person, which the judging guidelines explicitly penalize on this dimension; the capability statements themselves are properly third person ('Merges', 'Validates').

4 / 5

Completeness

Both 'what' and 'when' are explicit: the 'what' is a full pipeline ('Merges two or more security scanner reports into one gate' plus the normalize/dedupe/enrich/waive/verdict chain), and the 'when' is a concrete trigger phrase ('Use when you need a single BLOCK or PASS decision from multiple scanners instead of reading N separate reports') reinforced by positional guidance ('this runs after them to merge output').

5 / 5

Trigger Term Quality

Comprehensive natural-term coverage for the domain: users needing this skill would say 'security scanner reports', 'SAST', 'DAST', 'secret', 'dependency (SCA)', 'container', 'IaC', 'BLOCK or PASS', 'gate', 'deduplicate', 'CVE', 'waiver', and synonyms are included ('waiver (finding-suppression)', 'gate... single BLOCK or PASS decision'). Not a level-4 case since no commonly-used natural phrasing for this need is absent.

5 / 5

Distinctiveness Conflict Risk

It carves out a clear niche ('the cross-scanner gate, not a single-scanner wrapper') and actively steers wrong-skill triggers away ('To run a single scanner instead use semgrep-rules, codeql-queries, or one of the language-native-sast linters'), so conflict risk with sibling scanner skills is minimal — better than the level-4 'minor overlap risk' anchor.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

referenced_paths_exist

Referenced path issues: 1 missing

Warning

Total

15

/

16

Passed

Reviewed

Table of Contents